Executive brief
Pandora FMS, a monitoring and IT management platform, contains a vulnerability in its Network Report component. An attacker with low-level user access can execute unauthorized commands on the underlying operating system. This could lead to a complete takeover of the monitoring server, potentially exposing sensitive infrastructure data or disrupting IT operations.
Technical details
An OS Command Injection vulnerability (CWE-78) exists in Pandora FMS versions 777 through 800. The flaw is located within the Network Report functionality, where the application fails to properly neutralize special elements used in operating system commands. An attacker with low-privileged (PR:L) network access can exploit this by submitting specially crafted input to the Network Report feature, leading to arbitrary command execution with the privileges of the web server user. A fix is available in version 800.1.
Affected products
- Artica PFMS Pandora FMS 777 through 800
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory: Initial advisory from Artica PFMS
- 2026-04-22: patched: NIST analysis confirms fix in version 800.1